PT-2026-35063 · 4Gaboards · 4Gaboards

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-41418

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions 4ga Boards versions prior to 3.3.5
Description 4ga Boards is a boards system for realtime project management. The software allows user enumeration through a timing side-channel in the login endpoint '/api/access-tokens'. The server responds significantly faster when an invalid username or email is provided compared to when a valid one is used with an incorrect password. This difference occurs because the server executes the bcrypt.compareSync() function only when a valid user is identified, creating a detectable timing gap that can be used to verify the existence of users.
Recommendations Update to version 3.3.5.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41418

Affected Products

4Gaboards